Bitcoin Forum

Economy => Collectibles => Topic started by: krogothmanhattan on December 16, 2023, 09:54:21 AM



Title: [INFO} Be aware of https://privnote.co/
Post by: krogothmanhattan on December 16, 2023, 09:54:21 AM
  This was brought up in the past but wanted to make a new thread for people that are not aware of this scam site. https://privnote.co/

    I was using the cell phone and googled privnote to send in private a message to another user...and guess what was on the very top of the search results...yep the scam site https://privnote.co/



   https://www.talkimg.com/images/2023/12/16/ErF2b.jpeg





   So for the unaware....I pasted a BTC addy in and created the link as follows...




      https://www.talkimg.com/images/2023/12/16/ErNRv.png






     Then when I copied the link and opened it up....voila.....a new BTC addy that I assume goes to the scammers wallet!




          https://www.talkimg.com/images/2023/12/16/ErE1H.png





    SO be very very careful out there! Also on another note....I tried the google search the same way I did on my phone and that top results was actually the real site...not sure why the fake one comes on my cell though





     https://www.talkimg.com/images/2023/12/16/ErIWg.png
  


Title: Re: [INFO} Be aware of https://privnote.co/
Post by: FatFork on December 16, 2023, 11:19:26 AM
    Then when I copied the link and opened it up....voila.....a new BTC addy that I assume goes to the scammers wallet!

It seems this sneaky scammer set things up to swap out any Bitcoin address folks try to use with their own address instead.  Just tried it out myself, and no matter what I typed in that looked like legacy BTC public address (even incomplete and incorrect ones), it got replaced with 1BfxN3HCLofTgZAF1g8xxbqMhdVARpqCbM.  Yeah pretty sure that one goes straight to the thief who cooked this up. 

And unfortunately , just yesterday some poor sucker sent 0.12 btc from Binance right to that scammer's pocket.

https://blockchair.com/bitcoin/address/1BfxN3HCLofTgZAF1g8xxbqMhdVARpqCbM


Title: Re: [INFO} Be aware of https://privnote.co/
Post by: dkbit98 on December 16, 2023, 01:38:37 PM
This was brought up in the past but wanted to make a new thread for people that are not aware of this scam site.
I think you should post about this in Scam Accusation board to get more attention, not everyone is often visiting Collectibles board.

I don't remember noticing anything about privnote in bitcointalk forum, but I have seen similar tools.
Note that logo and domain is obviously different from real privnote project.

scam:
https://www.talkimg.com/images/2023/12/16/E1RyD.jpeg
Code:
https://privnote.co/ 

legit:
https://www.talkimg.com/images/2023/12/16/E1PMG.jpeg
Code:
https://privnote.com/


Title: Re: [INFO} Be aware of https://privnote.co/
Post by: MoparMiningLLC on December 16, 2023, 02:37:52 PM
yes there are several threads about the fake privnote sites

here are 2 more - one started just a few months ago.

https://bitcointalk.org/index.php?topic=5458055.0

and

https://bitcointalk.org/index.php?topic=5256113.0


Title: Re: [INFO} Be aware of https://privnote.co/
Post by: minerjones on December 16, 2023, 02:51:45 PM
Just use zerobin.net or their onion site on Tor... or better yet, just use PGP 8)


Title: Re: [INFO} Be aware of https://privnote.co/
Post by: tread93 on December 17, 2023, 02:51:42 AM
This was brought up in the past but wanted to make a new thread for people that are not aware of this scam site.
I think you should post about this in Scam Accusation board to get more attention, not everyone is often visiting Collectibles board.

I don't remember noticing anything about privnote in bitcointalk forum, but I have seen similar tools.
Note that logo and domain is obviously different from real privnote project.

scam:
https://www.talkimg.com/images/2023/12/16/E1RyD.jpeg
Code:
https://privnote.co/ 

legit:
https://www.talkimg.com/images/2023/12/16/E1PMG.jpeg
Code:
https://privnote.com/

Used to use this way back when it's a shame that all of these scams are happening but what else is new under the sun! It's a sneaky little truck they pull this fast one on with you here, don't use this to send your BTC Addy for payment or you'll never see the funds!! 


Title: Re: [INFO} Be aware of https://privnote.co/
Post by: krogothmanhattan on December 17, 2023, 08:14:11 AM
This was brought up in the past but wanted to make a new thread for people that are not aware of this scam site.
I think you should post about this in Scam Accusation board to get more attention, not everyone is often visiting Collectibles board.

I don't remember noticing anything about privnote in bitcointalk forum, but I have seen similar tools.
Note that logo and domain is obviously different from real privnote project.

scam:
https://www.talkimg.com/images/2023/12/16/E1RyD.jpeg
Code:
https://privnote.co/ 

legit:
https://www.talkimg.com/images/2023/12/16/E1PMG.jpeg
Code:
https://privnote.com/


 Good idea....did just that here https://bitcointalk.org/index.php?topic=5478237.0


Title: Re: [INFO} Be aware of https://privnote.co/
Post by: ChiBitCTy on December 17, 2023, 09:12:20 AM
Proof that google doesn’t give a fuck about anything but money. They are hands down the most advanced software company on the planet, and they aren’t able to quickly research ad companies before allowing them to advertise on their site. They already allowed this once, and not too long after (post having received countless complaints from people that this ad site they were promoting was actually a scammer pretending to be a legit company).  You guys think google might have software capabilities to ping past scams quickly even if they somehow unknowingly (which yeah right) allowed them back on.  I can’t even post a btalk link or write the letters “btalk” on YouTube without them deleting it within minutes. They allow for bot scammers to have fake convos all the f over the place, no problem.  Have google TV and want to share your password ? Impossible thanks to their industry best  GPS tracking software rendering it impossible.. Sickens me that they’ll never receive any sort of fine or punishment for these corrupt and illegal practices.


Title: Re: [INFO} Be aware of https://privnote.co/
Post by: aoluain on December 17, 2023, 08:00:21 PM
Absolutely not, its been happening on and off for years on google, I reported on something
similar a few years ago concerning a fake Trezor site > https://bitcointalk.org/index.php?topic=5205126.msg53198360#msg53198360

https://1.bp.blogspot.com/-mvWQ-BgcHs0/Xd7zeRn8cKI/AAAAAAAAAaw/-GJ-vjfXzkQ6ec2rnqOCeAy5eAdgkPYSQCNcBGAsYHQ/s1600/Capture01.PNG

Isnt amazing how these fakes end up on top of the legit site?

Thanks Krogo for highlighting this, just another reminder for us all to check and double
check before committing?

"measure twice, cut once"


Title: Re: [INFO} Be aware of https://privnote.co/
Post by: rsincognito on December 17, 2023, 09:54:48 PM
Wow thank you for sharing this ,  I just booked malted this website the other day in my office , I’m interested to know when I get into work which one I booked marked the fake one or the real one


Title: Re: [INFO} Be aware of https://privnote.co/
Post by: krogothmanhattan on December 18, 2023, 03:58:46 PM
  Look at this way...If I ever had to receive or send a large amount of BTC, then I would send the BTC addy thru two different channels...example would be thru signal and also thru encrypted email. If they both match then I am ok,,,as I do worry about the man in the middle attack.

  Another way I make sure the addy is good is, I would send or received say $10 in BTC and once that has arrived in good condition, then you are good to go. Have done this many times, and it will never fail you.


Title: Re: [INFO} Be aware of https://privnote.co/
Post by: rsincognito on December 18, 2023, 06:00:55 PM
  Look at this way...If I ever had to receive or send a large amount of BTC, then I would send the BTC addy thru two different channels...example would be thru signal and also thru encrypted email. If they both match then I am ok,,,as I do worry about the man in the middle attack.

  Another way I make sure the addy is good is, I would send or received say $10 in BTC and once that has arrived in good condition, then you are good to go. Have done this many times, and it will never fail you.

I like the idea of using signal app and the correct privnote and then to compare for the match.


Title: Re: [INFO} Be aware of https://privnote.co/
Post by: bitbollo on December 18, 2023, 06:04:44 PM
 Look at this way...If I ever had to receive or send a large amount of BTC, then I would send the BTC addy thru two different channels...example would be thru signal and also thru encrypted email. If they both match then I am ok,,,as I do worry about the man in the middle attack.

  Another way I make sure the addy is good is, I would send or received say $10 in BTC and once that has arrived in good condition, then you are good to go. Have done this many times, and it will never fail you.

I never click/open on sponsored content precisely because it is not the first time that this mechanism has been exploited to defraud crypto users.

great suggestions above...
Sending a test payment is also a good idea.
considering the price of the fees, at least now, it is a fairly expensive solution.

By the way I have another solution/idea to that issue.

I Will send my address as usuale with privnote but I will send via DM sha256 of my address!

1BoSH7RisUAPpGfNbX8scSB43YP6Tx3g7M

309ca0daa75eb6970eec4d0f8f013e5310babcf25ea330d3e605a65e825e67ff

https://emn178.github.io/online-tools/sha256.html?input_type=utf-8&input=1BoSH7RisUAPpGfNbX8scSB43YP6Tx3g7M&hmac_input_type=utf-8

These data can be verified by anyone and doesnt requires any specific software/setup


Title: Re: [INFO} Be aware of https://privnote.co/
Post by: dkbit98 on December 18, 2023, 10:24:47 PM
  Look at this way...If I ever had to receive or send a large amount of BTC, then I would send the BTC addy thru two different channels...example would be thru signal and also thru encrypted email. If they both match then I am ok,,,as I do worry about the man in the middle attack.
I think there are better options than signal now, maybe something like simplex chat, first messenger without using any user IDs.
It's open source, it has end-to-end encryption and you dont need to use phone numbers or other identity.
Another good thing about Simplex chat is that you can use both on mobile devices and desktop computers (Linux, Mac, win).

Another way I make sure the addy is good is, I would send or received say $10 in BTC and once that has arrived in good condition, then you are good to go. Have done this many times, and it will never fail you.
Not ideal thing to do when fess are crazy high  :P


Title: Re: [INFO} Be aware of https://privnote.co/
Post by: krogothmanhattan on December 19, 2023, 09:57:18 AM
  Look at this way...If I ever had to receive or send a large amount of BTC, then I would send the BTC addy thru two different channels...example would be thru signal and also thru encrypted email. If they both match then I am ok,,,as I do worry about the man in the middle attack.
I think there are better options than signal now, maybe something like simplex chat, first messenger without using any user IDs.
It's open source, it has end-to-end encryption and you dont need to use phone numbers or other identity.
Another good thing about Simplex chat is that you can use both on mobile devices and desktop computers (Linux, Mac, win).

Another way I make sure the addy is good is, I would send or received say $10 in BTC and once that has arrived in good condition, then you are good to go. Have done this many times, and it will never fail you.
Not ideal thing to do when fess are crazy high  :P

  Very true about the fees. However if I am sending a 1 BTC or more transaction, I would not mind eating a $20 twice to make sure my BTC ends up at the right addy. Small price to pay for peace of mind IMO.


Title: Re: [INFO} Be aware of https://privnote.co/
Post by: ChiBitCTy on December 20, 2023, 01:22:14 AM
 Look at this way...If I ever had to receive or send a large amount of BTC, then I would send the BTC addy thru two different channels...example would be thru signal and also thru encrypted email. If they both match then I am ok,,,as I do worry about the man in the middle attack.
I think there are better options than signal now, maybe something like simplex chat, first messenger without using any user IDs.
It's open source, it has end-to-end encryption and you dont need to use phone numbers or other identity.
Another good thing about Simplex chat is that you can use both on mobile devices and desktop computers (Linux, Mac, win).

Another way I make sure the addy is good is, I would send or received say $10 in BTC and once that has arrived in good condition, then you are good to go. Have done this many times, and it will never fail you.
Not ideal thing to do when fess are crazy high  :P

WeChat hands down the best. Ran by the most trustworthy man on the planet who’s never stolen anyone’s private data ;)

On a serious note, what are your thoughts here ?  https://www.reddit.com/r/privacy/s/t7dmB9s5VN

Edit- sent wrong link now trying to find the signal vs simplex discussion I thought I had copied..can’t seem to find. Will update shortly


Title: Re: [INFO} Be aware of https://privnote.co/
Post by: polymerbit on December 20, 2023, 09:28:22 AM
The website has tricked us before. Luckily, we managed to change passwords in time.